CardThesis
How it worksFeaturesWhy CardThesis
Sign in
LEGAL / PRIVACY

Privacy Policy

Effective September 23, 2026

CardThesis is a collectible intelligence platform currently in private development. This policy explains how information is handled on cardthesis.com and how account features are intended to work when they are made available.

Information we may collect

When you browse our public website, our hosting and infrastructure providers may process standard technical information such as IP address, browser type, device information, timestamps, and request logs for security, reliability, and performance.

When you use account features, CardThesis may store information you choose to provide, such as collection holdings, watchlist items, grading submissions, preferences, and other account-specific product data.

Google Sign-In

When Google Sign-In is enabled and you choose to use it, CardThesis may receive your Google account identifier, email address, display name, and profile image. CardThesis does not receive or store your Google password. We do not request access to your Gmail, Google Drive, Google Calendar, contacts, or other Google account content unless a future feature clearly asks for additional permission and this policy is updated first.

How we use information

We use information to provide and secure the CardThesis service, maintain your account and product data, improve product performance, respond to support requests, prevent abuse, and comply with legal obligations.

Card and grading images

CardThesis is designed so grading-analysis photos can be processed for an assessment without becoming a permanent photo archive by default. If hosted photo-analysis features are launched, retention behavior will be disclosed in the product and this policy before use.

CardThesis photo matching on Android

Android builds with the CardThesis photo scanner read card details on the device using Google's bundled ML Kit text-recognition library. Taking or choosing a photo starts identification: the photo and limited card-name and number hints are sent to CardThesis, where our image-matching code compares them with catalog artwork. This path does not call OpenAI or fall back to another paid AI provider. Image similarity does not establish an exact release, stamp, finish or authenticity; review the match and printing before saving.

The scanner processes photos and hints for the current request without creating a server-side photo archive, logging their contents or adding them to a training set. Only public catalog artwork features are cached. Retaking a photo, leaving the scanner or changing accounts clears its in-memory photo and result; temporary image files can remain in the app's device cache. Manual catalog search sends only the fields you enter. Saving a reviewed card uses the normal Collection editor.

Older Android builds and the web scanner can still use OpenAI for photo identification and verification. Their behavior is separate from the new Android CardThesis photo scanner. Older builds may also offer a local text test and an optional report share sheet: those reports include recognized text, positions, raw scores, timing, an input fingerprint and the app revision, but no photo bytes or account details. Review any report before sharing it with a recipient.

Google states that ML Kit processes its image inputs and results on the device. The ML Kit SDK sends usage and performance information to Google, including device and application information, per-installation identifiers, and processing metrics. See ML Kit terms and privacy and Google's Android data disclosure.

Sharing and selling

We do not sell personal information. We may use service providers to operate infrastructure, authentication, hosting, analytics, security, or product functionality. Those providers may process information only as needed to deliver their services to CardThesis.

Your Collection is private by default. If you deliberately enable an unlisted Collection share link, CardThesis may make the collection fields you selected visible to anyone who has that link until you disable sharing or regenerate the link. Public Collection views are designed to exclude owner identity, purchase price, profit/loss, grading costs, private notes, acquired dates, and private database row identifiers.

Paper Trading and optional Paper Leagues

Private practice portfolios and Paper League entries are separate. A league is optional and each round requires its own explicit join. We store your chosen handle, the round, the sharing disclosure and rules you accepted, acceptance time, simulated orders, valuations and any withdrawal. Your account identifier links these records privately; your Google name, email and profile image are not used to prefill a league handle.

If you join a round, signed-in, non-anonymous CardThesis members can see your chosen handle, rank, percentage return and simulated profit, along with the round and standings timestamp. They cannot see your account identifier, email, profile image, individual holdings, orders, private practice portfolios or real Collection through the league standings. Browsing standings does not enroll you, join future rounds or enable notifications.

Leaving a round removes your identifiable entry from its current and historical shared standings. Your private round record, orders and acceptance receipt remain associated with your account for your history and round integrity; leaving does not reset the round or allow re-entry. Copies or screenshots already made by others cannot be recalled. Account-data access and deletion requests use the contact below.

The app may keep an unfinished order identifier and its exact order details in secure device storage until its result is resolved, to prevent a connection retry from placing the same order twice. Shared standings and consent choices are not saved there.

Data security

CardThesis is being designed around managed authentication, database-level access controls, and server-side handling of private API credentials. No security method is perfect, but we aim to minimize the personal and credential data CardThesis needs to hold.

Data choices and deletion

You may request access to or deletion of account data by contacting privacy@cardthesis.com.

Children

CardThesis is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes to this policy

We may update this policy as CardThesis moves from private development to public availability. The effective date at the top of this page will identify the current version.

Contact

For privacy questions, contact privacy@cardthesis.com.

CardThesis

Your cards, explained.

hello@cardthesis.com

ProductHow it worksFeaturesWhy CardThesis
CompanyPrivacyTermsContact
© 2026 CardThesis. All rights reserved.Independent collector utility · Not affiliated with or endorsed by The Pokémon Company.